OSCP+ Exam 2026 Guide: Format, Cost, Requirements, Training & Preparation

 

The OSCP+ exam is OffSec’s hands-on certification assessment for penetration testers. Candidates receive 23 hours and 45 minutes to compromise systems in a private VPN, then another 24 hours to submit a professional penetration-test report. The exam is scored out of 100 points: three standalone machines are worth 60 points and one three-machine Active Directory set is worth 40. A score of 70 is required. Passing awards both OSCP and OSCP+; OSCP+ expires after three years, subject to OffSec renewal.

What Is OSCP+?

OSCP+, formally OffSec Certified Professional Plus, is a practical offensive security certification designed to validate real penetration-testing ability. Instead of relying on conventional multiple-choice questions, candidates must identify vulnerabilities, gain access to systems, escalate privileges, work through an Active Directory environment, and document what they accomplished.

For anyone researching what is OSCP+, what is an OSCP, or an OSCP offensive security certification overview, the key point is that this credential focuses on demonstrated technical performance.

Candidates who pass the current exam receive both the OSCP and OSCP+ certification. OSCP remains valid indefinitely, while OSCP+ has a three-year validity period.

That distinction makes the offensive security OSCP+ certification useful for professionals who want a continuously maintained credential while retaining the permanent OSCP certification.

The terms Offensive Security Certified Professional certification, OSCP certification OffSec, OSCP offensive security certification, and Offensive Security Certified Professional OSCP certification all refer to this OffSec penetration-testing certification path.

OSCP+ Exam Format and Passing Score

The current OSCP certification exam is remotely proctored and conducted in a private VPN environment. Candidates receive 23 hours and 45 minutes to complete the technical assessment and another 24 hours after the exam to submit their documentation.

Exam Component

Machines

Points

Primary Objective

Standalone systems

3

60

Initial access and privilege escalation

Active Directory set

3

40

Compromise an AD environment

Total

6

100

Practical penetration testing

Passing requirement

70/100

Reach at least 70 points

Each standalone target is worth 20 points: 10 points for initial access and 10 for privilege escalation. The Active Directory set contributes the remaining 40 points. OffSec publishes several possible combinations for reaching the required 70 points.

A critical part of the OSCP+ exam is reporting. Candidates must submit evidence explaining how the objectives were achieved, including appropriate screenshots and technical reproduction details.

This means passing is not simply about getting shells. Evidence collection and documentation are part of the skill being assessed.

OSCP Certification Requirements

There are currently no formal OSCP certification requirements such as another certification, degree, or mandatory work-experience threshold before attempting OSCP+.

OffSec also confirms that completing PEN-200 is not mandatory before purchasing the standalone exam. It is, however, strongly recommended for candidates who do not already have substantial practical penetration-testing experience.

Before beginning an OSCP certification course or serious preparation, candidates should understand:

  • TCP/IP networking

  • Linux command-line administration

  • Windows administration

  • DNS, HTTP, SMB and common network services

  • Basic Bash or Python scripting

  • Enumeration techniques

  • Vulnerability identification

  • Basic web exploitation

  • Linux and Windows privilege escalation

OffSec specifically recommends networking knowledge, reasonable Linux and Windows experience, and familiarity with scripting.

“No formal prerequisite” should therefore not be confused with “beginner-level exam.”

What Does OSCP Training Cover?

The official Offensive Security OSCP course is PEN-200: Penetration Testing with Kali Linux. OffSec describes PEN-200 as a hands-on, learn-by-doing foundational penetration-testing course.

The current OSCP+ body of knowledge covers areas including information gathering, vulnerability scanning, web application testing, exploitation, privilege escalation, Active Directory techniques and professional penetration-testing documentation.

Effective OSCP training and offensive security training should develop a repeatable methodology:

  1. Enumerate the target — discover ports, services, users, shares, directories and technologies.

  2. Analyze findings — determine which information creates a realistic attack path.

  3. Gain initial access — exploit an appropriate vulnerability within the authorized environment.

  4. Escalate privileges — investigate services, permissions, credentials and configurations.

  5. Attack AD systematically — understand users, systems, authentication and privilege relationships.

  6. Document immediately — record commands, screenshots, credentials and proof while working.

For candidates comparing OSCP training online, OSCP online training, an OSCP online course, or an OSCP preparation course, the amount of independent lab practice is more important than the number of recorded lessons.

Good OSCP ethical hacking preparation should make you solve problems rather than simply copy commands.

OSCP Certification Cost in 2026

OffSec pricing checked on August 19, 2026 lists several ways to pursue the certification.

Option

Listed Price

Includes

OSCP+ Standalone Exam

$1,699

Two exam attempts within 90 days; no PEN-200 course

Course + Cert Bundle

$1,749

90 days of course/lab access and one exam attempt

Learn One

$2,749/year

One year of selected course/lab access plus certification attempts

The standalone route may suit an experienced offensive security professional who already has sufficient lab skills. Candidates who need structured preparation may receive greater value from a package containing PEN-200.

When researching OSCP certification cost, OSCP training cost, OSCP certification exam cost, Offensive Security Certified Professional cost, or broader offensive security certification cost, confirm current pricing directly with OffSec before purchasing because packages and prices may change.

If you searched for “ocsp certificate cost,” the certification acronym you are probably looking for is OSCP, not OCSP.

OSCP vs CEH: Which Certification Should You Choose?

The OSCP vs CEH comparison is best approached according to your career objective rather than asking which credential is universally better.

Factor

OSCP+

CEH

Primary focus

Practical penetration testing

Broad ethical-hacking knowledge and skills

Main exam style

Extended hands-on assessment

125-question knowledge exam

Additional practical option

Built into OSCP+ assessment

Separate CEH Practical available

Reporting

Required

Not central to CEH knowledge exam

Strong fit

Pen testing and offensive roles

Broad ethical-hacking foundation

OffSec’s exam centers on hands-on compromise and reporting. EC-Council’s current CEH pathway includes a four-hour, 125-question knowledge exam and also offers a separate six-hour practical assessment with 20 challenges.

For CEH vs OSCP, OSCP+ is especially relevant when you want to prove sustained practical ability in enumeration, exploitation, privilege escalation and Active Directory.

CEH can make sense when broader structured ethical-hacking coverage is the immediate priority.

How to Prepare for the OSCP+ Exam

A strong ethical hacking offensive penetration testing OSCP prep strategy should measure your ability to solve unfamiliar problems independently.

Build a Repeatable Enumeration Process

Create separate checklists for:

  • Linux targets

  • Windows targets

  • Web applications

  • SMB and network services

  • Privilege escalation

  • Active Directory

Do not let a favorite exploitation tool replace enumeration.

Practice Without Walkthroughs

Walkthroughs are useful for learning new techniques but poor at measuring exam readiness. Gradually move toward machines where you must develop the attack path yourself.

Practice Reporting Alongside Hacking

After completing a machine, write a concise report containing the vulnerability, exploitation steps, commands, evidence and privilege-escalation path.

This converts reporting into routine rather than an extra task after hours of technical work.

Use a Structured Training Schedule

OffSec currently publishes both 12-week and 24-week PEN-200 learning plans, reinforcing the value of systematic preparation.

OffSec also states that PEN-200 course exercises typically require more than 40 hours, separate from the additional time candidates may spend on challenge labs and independent practice.

Whether you use official PEN-200, another OSCP training course, or an OSCP prep course, measure progress through independent execution rather than hours watched.

How Long Is OSCP+ Valid?

The OSCP+ cert is valid for three years. The OSCP credential awarded alongside it remains valid indefinitely.

OffSec currently provides several routes for maintaining qualifying certifications. Its CPE framework allows eligible certification holders to earn 120 CPE credits across a three-year certification cycle while maintaining the required annual coverage.

Qualifying OffSec certification exams may also extend OSCP+ validity under OffSec's renewal rules.

Anyone comparing offensive security certs should account for renewal requirements rather than looking only at the initial exam.

Is the OSCP+ Certification Worth Pursuing?

OSCP+ makes the most sense when your goal requires genuine offensive-security execution rather than certification knowledge alone. OffSec identifies roles such as penetration tester, security consultant and other security-focused positions as relevant paths for OSCP-certified professionals.

The strongest preparation strategy is straightforward: develop networking and operating-system fundamentals, complete substantial hands-on OSCP pen testing practice, build a consistent enumeration methodology, learn to recover from failed attack paths, and become comfortable producing technical documentation.

Do not schedule the exam simply because you finished an OSCP certification training program. Schedule it when you can take an unfamiliar target from enumeration → initial access → privilege escalation → evidence → report without depending on a walkthrough.

For authoritative Offensive Security OSCP certification official information, verify the latest exam rules, pricing, candidate policies and renewal requirements through OffSec before registration.


Comments

Popular posts from this blog

How Long to Study for CEH Certification: A Complete Guide

All About CompTIA Data+

The Role of a Client Success Manager in Driving Growth